High severity8.8NVD Advisory· Published Jun 12, 2023· Updated Jun 17, 2026
CVE-2023-34468
CVE-2023-34468
Description
The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution.
The resolution validates the Database URL and rejects H2 JDBC locations.
You are recommended to upgrade to version 1.22.0 or later which fixes this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.nifi:nifi-dbcp-baseMaven | >= 0.0.2, < 1.22.0 | 1.22.0 |
org.apache.nifi:nifi-hikari-dbcp-serviceMaven | >= 0.0.2, < 1.22.0 | 1.22.0 |
org.apache.nifi:nifi-dbcp-service-narMaven | >= 0.0.2, < 1.22.0 | 1.22.0 |
Affected products
6- osv-coords4 versionspkg:bitnami/nifipkg:maven/org.apache.nifi/nifi-dbcp-basepkg:maven/org.apache.nifi/nifi-dbcp-service-narpkg:maven/org.apache.nifi/nifi-hikari-dbcp-service
>= 0.0.2, < 1.22.0+ 3 more
- (no CPE)range: >= 0.0.2, < 1.22.0
- (no CPE)range: >= 0.0.2, < 1.22.0
- (no CPE)range: >= 0.0.2, < 1.22.0
- (no CPE)range: >= 0.0.2, < 1.22.0
Patches
Vulnerability mechanics
References
12- packetstormsecurity.com/files/174398/Apache-NiFi-H2-Connection-String-Remote-Code-Execution.htmlnvdThird Party AdvisoryVDB EntryWEB
- www.openwall.com/lists/oss-security/2023/06/12/3nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-xm2m-2q6h-22jwghsaADVISORY
- lists.apache.org/thread/7b82l4f5blmpkfcynf3y6z4x1vqo59h8nvdMailing ListVendor AdvisoryWEB
- nifi.apache.org/security.htmlnvdRelease NotesVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-34468ghsaADVISORY
- www.cyfirma.com/outofband/apache-nifi-cve-2023-34468-rce-vulnerability-analysis-and-exploitation/nvdThird Party Advisory
- exceptionfactory.com/posts/2023/10/07/firsthand-analysis-of-apache-nifi-vulnerability-cve-2023-34468ghsaWEB
- github.com/apache/nifi/commit/4faf3ea59895e7e153db3f8f61147ff70a254361ghsaWEB
- github.com/apache/nifi/pull/7349ghsaWEB
- issues.apache.org/jira/browse/NIFI-11653ghsaWEB
- www.cyfirma.com/outofband/apache-nifi-cve-2023-34468-rce-vulnerability-analysis-and-exploitationghsaWEB
News mentions
0No linked articles in our index yet.